1 to 25 of 82 Permanent MITRE ATT&CK Jobs in London

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
processes to improve the quality and relevance of CTI outputs. Analyse threat actor behaviour and map activity to frameworks such as MITRE ATT&CK to support defensive strategy and risk‐based decision‐making. Brief technical, business, and senior leadership stakeholders on cyber threats, trends, potential … function. Demonstrated experience conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including use of MITRE ATT&CK or similar frameworks to structure analysis and communicate adversary behaviour. Strong understanding of the intelligence lifecycle, including requirements, collection, analysis, dissemination ...

Cloud Platform Security Engineer Software engineering London

Location
Greater London, England, United Kingdom
modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI DSS, SOC2, ISO27001 NIST … Python, PowerShell, or Bash for security automation. Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Nice to have AZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification. Experience integrating ATT&CK ...

Cyber Security Engineer - Threat Detection

Location
City Of London, England, United Kingdom
health for assigned detection areas, including retiring logic that no longer earns its place Detection Coverage - Map detection coverage to the MITRE ATT&CK framework, identify gaps, and propose the telemetry or logic needed to close them Threat Intelligence Integration - Convert threat intelligence reporting into … ability to investigate suspicious activity end to end: read the logs, form a conclusion, and communicate it clearly Familiarity with the MITRE ATT&CK framework and the ability to reason about adversary tradecraft rather than only indicators Solid understanding of operating system internals, networking ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
playbooks, runbooks, and standard operating procedures. Stay current with the evolving threat landscape, attacker TTPs (mapped to frameworks such as MITRE ATT&CK), and industry best practices. Required Qualifications, Capabilities, and Skills Demonstrable experience in a SOC, incident response, or security analyst role (typically 2+ … across SIEM, EDR/XDR, and network security tooling. Working knowledge of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework. Strong understanding of core networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and operating system internals (Windows ...

Security Consultant

Location
Greater London, England, United Kingdom
platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat techniques. Assessing customer telemetry and identifying opportunities to improve visibility and detection coverage. Building SOAR automations, integrations and response … platforms such as Microsoft Logic Apps, Cortex XSOAR or equivalent. Python, PowerShell or other scripting languages for automation and API integration. MITRE ATT&CK and threat-informed detection engineering. XDR/EDR technologies including Microsoft Defender, CrowdStrike, Cortex XDR or SentinelOne. Azure security monitoring ...

Security Operations Engineer

Hiring Organisation
CloudBees
Location
London, UK
Employment Type
Full-time
Create high-fidelity detections using operational threat intelligence, incident learnings and purple team findings. Measure and improve detection coverage using the MITRE ATT&CK framework. Continuously reduce false positives while improving visibility into emerging attacker techniques. SOAR & Automation EngineeringDesign and maintain SOAR playbooks that automate … similar languages. Experience working within cloud environments (AWS preferred; Azure or GCP experience also valued). Solid understanding of the MITRE ATT&CK framework. Experience supporting security incident response. Comfortable working with Git, APIs and engineering workflows. Excellent communication skills with both Security and Engineering ...

SOC Team Lead

Location
Greater London, England, United Kingdom
familiarity with Sentinel, Defender, Splunk, or CrowdStrike Desirable: experience contributing to GRC or ISO standards Desirable: knowledge of ITIL, NIST, or MITRE ATT&CK frameworks Desirable: understanding of customer impact and stakeholder management within cyber contexts Awareness of applicable regulations and frameworks such as NCSC … Mentoring Relationship Building Stakeholder Management Certifications & Qualifications CompTIA Security+ CISSP Industry Keywords Cyber Hygiene NIST ISO27001 Cyber Essentials Plus GRC ITIL MITRE ATT&CK NCSC Tools & Technologies SIEM EDR Sentinel Defender Splunk CrowdStrike #J-18808-Ljbffr ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment and security scanning activities using relevant tools. Provide input into penetration testing activities and interpret findings … Security (ES). Solid understanding of network protocols, cloud security (AWS/Azure), and threat detection methodologies. Working knowledge of the MITRE ATT&CK framework. Experience building automation or SOAR playbooks for security operations. CrowdStrike certifications (CCFA/CCFR/CCSE – any combination preferred). ...

Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
threat detection platforms.Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.Validate detections through testing, simulation exercises … more of the following:Splunk and SPLYARA rule developmentEDR detection engineeringSIEM content development and tuningExperience mapping detections to the MITRE ATT&CK framework.Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.Desirable ExperienceExperience with Cribl and security data ...

Senior Security Engineer

Hiring Organisation
Docebo
Location
London, United Kingdom
exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.Vulnerability & Configuration Management: Own vulnerability management for cloud workloads — prioritizing findings from cloud configuration assessments, and runtime protection tools. Drive … multi-cloud exposure is a plus.In-depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well-Architected Security Pillar, NIST CSF, SOC 2, ISO 27001.Willingness and ability to participate in an on-call ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud. Vulnerability & Configuration Management: Own vulnerability management for cloud workloads - prioritizing findings from cloud configuration assessments, and runtime protection tools. … multi‐cloud exposure is a plus. In‐depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well‐Architected Security Pillar, NIST CSF, SOC 2, ISO 27001. Willingness and ability to participate ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
proactive threat hunting based on attacker behaviour, not vendor alertsTranslating threat intelligence and incident learnings into durable, reusable detectionsMapping detections to MITRE ATT&CK and real-world attack pathsReducing alert fatigue through logic refinement, correlation, and contextual enrichmentAdvising and supporting during high-severity security incidents … plane, SaaS)Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Additional InformationBring all of you to workWe create the conditions for high performers to thrive, through real ownership, fewer ...

Senior Cyber Detection and Response Engineer

Location
Greater London, England, United Kingdom
build and continuously improve detection content, managed as code and version-controlled, mapping coverage to adversary tactics and techniques using the MITRE ATT&CK framework and prioritising the techniques most relevant to a financial services SaaS provider. Telemetry and visibility – maintain a clear view … detections. Working knowledge of cloud security and native cloud telemetry sources (AWS and/or Azure). Practical use of the MITRE ATT&CK framework to structure detection coverage and gap analysis. Hands-on experience building and operating SOAR playbooks and response automation, orchestrating across ...

SecOps Engineer

Location
City Of London, England, United Kingdom
engineering and tuning Build, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK framework Continuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approach Identify gaps in detection … Python, PowerShell or KQL, with a working understanding of APIs and integration patterns Practical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetry A proactive mindset: the candidate must be able to point to specific examples where they ...

Senior Developer Experience Security Engineer

Location
Greater London, England, United Kingdom
tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners. Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs). Knowledge of security standards and frameworks (e.g. ISO27001, NIST CSF, AWS FSBP) is beneficial. Relevant security certifications (e.g. GCLD … tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners. Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs). Knowledge of security standards and frameworks (e.g. ISO27001, NIST CSF, AWS FSBP) is beneficial. Relevant security certifications (e.g. GCLD ...

Director - Security Architecture

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
risks into practical engineering requirements. Drive a threat-led approach to security , using threat modelling, attacker behaviour and frameworks such as MITRE ATT&CK to inform architecture decisions and prioritise controls. Shape security across the complete software delivery lifecycle, including secure SDLC, application security, vulnerability … security . Fluent English and comfortable collaborating across international teams and time zones. Experience with product security, SaaS/software environments, MITRE ATT&CK, infrastructure or network engineering would be valuable, but isn’t essential. Relevant security certifications such as CISSP, CCSP, CSSLP, GIAC ...

Principal Security Design Consultant

Location
Greater London, England, United Kingdom
management and data-residency requirements across cloud, on-premises and third-party services. Develop detection and response architectures covering analytics rules, MITRE ATT&CK-aligned use cases, threat hunting, workbooks, watchlists, automation and SOAR playbooks. Design secure integrations with ITSM, CMDB, threat intelligence, vulnerability management … QRadar, Rapid7 or Elastic. Experience with KQL, Sigma, Logic Apps, PowerShell or other automation and detection‐as‐code approaches. Knowledge of MITRE ATT&CK, NIST SP 800-61, NCSC CAF and recognised security operations maturity models. Experience of ITIL‐aligned service design, service transition ...

Cyber Security Analyst

Hiring Organisation
Damia Group
Location
City of London, London, United Kingdom
team. Key Responsibilities Conduct Threat Modelling using established and documented methodologies. Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats. Identify vulnerabilities using frameworks such as CWE and OWASP . Define, document and maintain appropriate security controls … Security . Strong experience in several of the following is required: Threat Modelling – essential , including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK. Professional experience working within a Cyber Security/Information Security role – essential . Identifying vulnerabilities using CWE and OWASP . Security principles covering ...

Cyber Risk & Security Manager

Location
Greater London, England, United Kingdom
decision‐making while driving operational security improvements aligned to recognised standards such as NIST CSF, ISO 27001, DORA, PCI‐DSS, and MITRE ATT&CK. Reporting To: Director/Head of Cyber Security Location: London (Hybrid) Employment Type: Full‐Time Salary: £50,000 – £70,000 (dependent on experience … writing and board‐level presentation capability. Experience leading client engagements and managing stakeholders. Ideally big 4 experience Technical Expertise Familiarity with MITRE ATT&CK and FAIR methodologies. Qualifications MSc in Cyber Security (or equivalent) CEH, CompTIA Security+ (required or equivalent experience) CE Advisor or prepared ...

Senior Cyber Analyst

Location
Greater London, England, United Kingdom
documentation, analytical, and stakeholder management skills. Desirable Certifications such as SC-200, SC-300, CISSP, GCIH, GCIA, or equivalent. Knowledge of MITRE ATT&CK, NIST Cyber Security Framework, and Zero Trust principles. Experience with PowerShell, Python, or security automation technologies. Experience contributing to cyber service ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Location
Greater London, England, United Kingdom
GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations. Experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements. Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations. Experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements. Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender ...

Threat Intelligence Analyst

Hiring Organisation
Matchtech
Location
London, UK
Employment Type
Full-time
Security initiatives within complex environments. Understanding of Security Architecture Design and secure-by-design principles. Familiarity with cyber frameworks such as MITRE ATT&CK, NIST, or Cyber Kill Chain. Experience producing intelligence reports and presenting findings to stakeholders. Strong analytical and problem-solving abilities. Excellent ...

Senior SOC Analyst – DV Clearance

Location
Greater London, England, United Kingdom
Understanding of network protocols, attack techniques, and cyber threat methodologies Experience investigating security incidents across Windows and Linux environments Knowledge of MITRE ATT&CK framework Familiarity with endpoint detection and response platforms *Rates depend on experience and client requirements #J-18808-Ljbffr ...

GRC Consultant

Location
Greater London, England, United Kingdom
list is not exhaustive): AD (Active Directory), Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualisation (VMware) Familiarity with MITRE ATT&CK Familiarity with ITIL Workplace type About NTT DATA NTT DATA is a $30+ billion business and technology services leader, serving ...